DORA financial entities: core BSIG duties do not apply
Section 28(6) no. 1 of the German BSIG exempts DORA financial entities from §§ 30, 31, 32, 35, 36, 38 and 39 BSIG; by its wording the exemption applies to the entity as a whole. ICT risk management and incident reporting run under DORA via BaFin. The BSI supervisory and enforcement powers under §§ 61 and 62 BSIG are not on that list and remain in place. So does registration under § 33 BSIG, provided the company counts as an essential or important entity under the BSIG.




